Executive brief
Digages Direct Payments WP is a WordPress plugin that handles payment processing for online transactions. The plugin contains a broken access control flaw that allows unauthorized users—specifically those with a Subscriber role—to access and perform payment-related actions they should not be permitted to execute. This could expose sensitive transaction data or allow unauthorized modification of payment settings.
Technical details
The vulnerability is a broken access control (authorization bypass) issue in Direct Payments WP version 1.3.2 and earlier. An attacker with a Subscriber-level account can bypass access control checks to view or modify payment-related data and functionality that should be restricted to higher-privilege users (such as administrators). The vulnerability requires authentication (Subscriber role or above) and can be exploited via network access to the WordPress site. No official patch is currently available, though the issue was reported in October 2025 and made public on 31 December 2025.
Affected products
- Digages Direct Payments WP <=1.3.2
Timeline
- 2025-10-07: disclosed: Initially reported to Patchstack
- 2025-12-31: advisory: Published by Patchstack and NVD as CVE-2025-49339